Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Decidim: JWT-backed authentication can be replayed across organizations (CVE-2026-45414)

0
High
Published: 07/13/2026 (07/13/2026, 17:16:56 UTC)
Source: GCVE Database
Product: decidim

Description

Decidim versions prior to 0.31.5 have a vulnerability where JSON Web Tokens (JWTs) issued for one organization can be replayed against another organization's API. This allows unauthorized access to sensitive participant details and mutation paths intended for that other organization. The issue arises because JWT authentication is not sufficiently bound to the host organization context, enabling cross-organization token reuse.

CVSS v3.1

Score 8.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Affected software

RubyGemsghsa
decidim
Affected versions
<0.31.5
RubyGemsghsa
decidim
Affected versions
>=0.32.0.rc1 <0.32.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/14/2026, 10:02:00 UTC

Technical Analysis

The vulnerability in Decidim involves insufficient binding of JWT-backed API authentication to the organization context. A JWT issued for an account in Organization 1 can be used to authenticate API requests against Organization 2's API, allowing access to admin-only GraphQL fields such as participantDetails and mutation paths like proposal.answer. This trust boundary violation enables an attacker with a valid JWT from one organization to read sensitive data from another organization. The problem affects API user authentication similarly. The root cause is that the current host selects the organization context but the JWT authentication does not verify that the token belongs to that organization. This vulnerability is tracked as CVE-2026-45414 and is classified under CWE-287 (Improper Authentication).

Potential Impact

An attacker with a JWT issued for one organization can replay that token against another organization's API, gaining unauthorized read access to sensitive participant personal data and the ability to invoke certain mutation operations. This breaks access control boundaries between organizations, potentially exposing confidential information and allowing unauthorized actions within other organizations' contexts. The CVSS vector indicates network attack vector, low attack complexity, requires privileges, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact.

Mitigation Recommendations

A fix is available in Decidim versions 0.31.5 and later, as indicated by the referenced pull requests (https://github.com/decidim/decidim/pull/16673 and https://github.com/decidim/decidim/pull/16756). Users should upgrade to version 0.31.5 or later to remediate this issue. As a workaround, disabling JWT credentials via the system panel (/system) can prevent exploitation until the patch is applied.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-r3v7-5x4c-c69q
Osv Schema Version
1.4.0
Aliases
["CVE-2026-45414"]
Ecosystems
["RubyGems"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a55ffbe68715ace432fb772

Added to database: 07/14/2026, 09:22:06 UTC

Last enriched: 07/14/2026, 10:02:00 UTC

Last updated: 07/31/2026, 12:27:30 UTC

Views: 52

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses